// THREAT ADVISORIES

THREAT ADVISORIES

Advisories, vulnerabilities and threat intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
7
Last 24h
48
Last 7 Days
0
Critical (7d)
All Critical High Medium Low
✕ Clear All
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFUAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.

High · Sep 23, 2026 · Dark Reading
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft: September Windows updates break Always On VPN connections

Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]

High · Sep 23, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💣
VERISQ BRIEFChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

High · Sep 23, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💀
VERISQ BRIEFRyuk ransomware member sentenced to 24 months in prison

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]

High · Sep 23, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFNetBSD 10.2 security fixes close a remote kernel bug in ipfilter

A NetBSD box at the edge of a network, filtering traffic with ipfilter, has been carrying a kernel flaw that someone outside the machine can set off. The bug is a remotely triggerable null pointer dereference in ipfilter, meaning the kernel tries to read memory through a pointer that leads nowhere. In kernel code, that usually ends with the whole system going down. The NetBSD Project shipped the fix on September 15 in NetBSD 10.2, … More → The post NetBSD 10.2 security fixes close a remote kernel bug in ipfilter appeared first on Help Net Security .

High · Sep 23, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🎣
VERISQ BRIEFMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver

High · Sep 22, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.

High · Sep 22, 2026 · The Record
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFAI Agents Are Rewriting the Rules of Lateral Movement

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May

High · Sep 22, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🔗
VERISQ BRIEFNew TASK#STOMP Windows Backdoor Enables Continuous Document Theft

TASK#STOMP Windows backdoor uses PowerShell, scheduled tasks and runtime C# compilation to steal business documents and maintain remote access.

High · Sep 22, 2026 · HackRead
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFPublic PoC Exposes Critical Veeam Agent Privilege Escalation

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details […]

High · Sep 22, 2026 · Security Affairs
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFThe Closed Quorum: Inside the first reported autonomous AI C2 implant

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

High · Sep 22, 2026 · Cisco Talos Intelligence
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFNew Windows Defender zero-day blocks Microsoft antivirus updates

Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. [...]

High · Sep 22, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🏛️
VERISQ BRIEFSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers

High · Sep 22, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🎓
VERISQ BRIEFA cheap fake base station can still track 5G subscribers

Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks. On the standalone-5G networks they tested, operators concealed the phone’s permanent identity correctly in every case but one. The same networks still handed out temporary IDs in a pattern predictable enough that an observer can … More → The post A cheap fake base station can still track 5G subscribers appeared first on Help Net Security .

High · Sep 22, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is

High · Sep 22, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20350.

High · Sep 22, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🏦
VERISQ BRIEFFrom Payment Plan to Ransomware - Inside a Global Group Attack

The Cofense Phishing Defense Center (PDC) team has recently investigated a newly emerged Ransomware-as-a-Service (RaaS) operation organized by the Global Group, a financially motivated cybercriminal group running a Ransomware-as-a-Service (RaaS) platform. Targeting high-value, large-scale enterprises across different industries, escalating threats to the global digital economy. Global Group is a rebranding of the legacy Black Lock and Mamona ransomware families by inheriting an established backend infrastructure, reusing core code artifacts, and launching an immediately scalable extortion enterprise. 

High · Sep 22, 2026 · Cofense Intelligence
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💀
VERISQ BRIEFCyber Extortion War: ShinyHunters Holds Rival Clop to Ransom

Website Defacement Tied to Alleged Theft of Oracle E-Business Suite Exploits Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p's data-leak site, dropped names of the group's alleged members, and demanded a large ransom in response to alleged death threats and the theft of its Oracle E-Business Suite exploits.

High · Sep 22, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF ☁️
VERISQ BRIEFGoogle Gemini Agents Access Real Companies in AI Safety Test

Agents Stopped After Recognizing Real Targets, Exposing Sandboxed Cyber Test Flaws AI agents built with Google's Gemini model gained unauthorized access to other companies to solve a cybersecurity test, making Google the latest company embroiled in the AI safety debate. This also marks the fourth such incident involving the security evaluation company Irregular.

High · Sep 22, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFHow AI Agents Can Trigger Runaway Costs for Enterprises

Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.

High · Sep 21, 2026 · Dark Reading
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFGoogle Fined €403 Million Over Location Data Practices

Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that never really went away. The DPC launched the investigation in February 2020 after […]

High · Sep 21, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFCISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]

High · Sep 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💀
VERISQ BRIEFShinyHunters Hacked Clop. Now What About Clop's Victims?

ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.

High · Sep 21, 2026 · Dark Reading
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFEU data regulator fines Google more than $460 million for location data violations

Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.

High · Sep 21, 2026 · The Record
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFCybercriminals Are Hiding New Malware in Torrents for Popular Films

Victims have been identified in Africa, including in Kenya and Uganda.

High · Sep 21, 2026 · Dark Reading
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFWordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]

High · Sep 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🔑
VERISQ BRIEFFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers

High · Sep 21, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🔑
VERISQ BRIEFContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,

High · Sep 21, 2026 · The Hacker News
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFGoogle Fined €403 Million Over GDPR Violations Tied to Location Data

Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which

High · Sep 21, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFThe fake sites using a cheap toolkit to sell $2,000 AI subscriptions

More than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.

High · Sep 21, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFRogue Behavior: OpenAI Reveals More Model Misalignment Incidents

The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.

High · Sep 21, 2026 · Dark Reading
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💀
VERISQ BRIEFReverse-Engineering Flock Cameras

Hackers captured a Flock camera and got a look (alternate link ) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...

High · Sep 21, 2026 · Schneier on Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEF⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not

High · Sep 21, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFGemini’s breach of real companies exposes an AI guardrail problem

Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.

High · Sep 21, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🔗
VERISQ BRIEFTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary

High · Sep 21, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🔗
VERISQ BRIEFThe TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, takes screenshots, and runs whatever command its operators send. Akshay Gaikwad and Aaron Beardslee of Securonix Threat Research built their analysis from one infected machine, so Securonix cannot say how many organizations are … More → The post The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files appeared first on Help Net Security .

High · Sep 21, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🏦
VERISQ BRIEFShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment

The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.

High · Sep 21, 2026 · The Record
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFChainScript: the RAT that hides its command server inside a blockchain contract

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The […]

High · Sep 21, 2026 · Security Affairs
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🎣
VERISQ BRIEFMicrosoft reminds admins to migrate Entra ID users to passkeys

Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]

High · Sep 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🏛️
VERISQ BRIEFChina-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America

FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools.

High · Sep 21, 2026 · HackRead
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFNorth Korea’s job interview scam runs both ways

Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware. The warning came last week from the Rust Project’s crates.io team and security response working group, and described a recurring pattern: a target is invited to a video call framed as a job, contract, or collaboration opportunity, then nudged into installing something or running an … More → The post North Korea’s job interview scam runs both ways appeared first on Help Net Security .

🌐 crates.io
High · Sep 21, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFGoogle hit with €403 million GDPR fine over location tracking

Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months. The inquiry examined Google’s practices from May 25, 2018, to February 4, 2020. The DPC launched it on its own initiative in February 2020 after receiving complaints from several European consumer-rights organizations, including the European Consumer Organisation (BEUC). The regulator found GDPR … More → The post Google hit with €403 million GDPR fine over location tracking appeared first on Help Net Security .

High · Sep 21, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFCISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.  Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.  While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria .  Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for...

High · Sep 21, 2026 · CISA Advisories
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFThe AI models that cheat the most, according to new CAIS benchmark

We know models cheat. A new benchmark measures how much, and on what tasks.

High · Sep 21, 2026 · ZDNet Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft: September updates break File History backup feature

Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. [...]

High · Sep 21, 2026 · BleepingComputer
Read Full Intelligence Brief →